![]() |
| [image source: DavidGallie on pixabay.com] |
Many stories* have emerged in the past year, claiming that rogue AIs have autonomously initiated attacks against various systems. A rational examination of the facts is necessary - and one must also take into account these contributing factors:
✅ An LLM/GenAI tool does not possess intelligence, awareness, or consciousness.
✅ An LLM does not have agency.
✅ An LLM does not have intent.
✅ An LLM does not have intrinsic goals.
✅ There was a prompt that initiated the subsequent behaviors/actions.
✅ The security and network guardrails were reduced/removed.
✅ There was a moronic level of network and cybersecurity incompetence involved – by not conducting the testing in air-gapped secure testing environments.
✅ The LLMs were trained on a vast corpus of books and internet-scraped content - that included sci-fi stories of rogue AIs; what-if cybersecurity scenarios; as well as actual content from various capture-the-flag competitions (which would have included summaries, scripts, code, logs, etc.) – thus, this alleged rogue AI behavior can be easily explained by understanding the next-token stochastic prediction mechanics of an LLM, with a vast AI token budget to experiment and explore millions/billions of possible paths.
* News Accounts of Rogue AI attacks:
Any stories that may attribute anthropomorphic intent (malevolent, or otherwise) – is merely an indication of the imbecilic limitations in the writer's understanding of how LLMs function.
@13:19 "We're not yet at the point where they autonomously grab computers and, you know, can't be shut down, [...] just sort of shows how nontechnical various people are."
– Bill Gates (2026-09-27 Sunday, Meet The Press interview)
- 2025-09-25 TheRegister: When AI is trained for treachery, it becomes the perfect agent
- 2026-05-12 TheRegister: Frontier AI safety tests may be creating the very risks they're meant to stop
- 2026-07-22 TheRegister: OpenAI admits it was the source of the agent swarm that attacked Hugging Face
- 2026-07-23 TheRegister: OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be
- 2026-07-31 TheRegister: Anthropic and OpenAI are competing to see whose agents can go rogue harder
- 2026-08-05 TheRegister: OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
- 2026-08-06 TheRegister: Meta latest to tell world its AI agent wandered out of test pen
- 2026-08-26 TheRegister: OpenAI explains how its naughty AI agents attacked Hugging Face
- 2026-09-08 TheRegister: OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
- 2026-09-09 TheRegister: Anthropic reveals fourth likely crime committed by its AI
- 2026-09-10 TheRegister: OpenAI's website-hijacking swarm reached far further than we thought
- 2026-09-14 TheRegister: Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent **
- 2026-09-17 TheRegister: OpenAI admits its agents went off the rails another six times
- 2026-09-20 OpenAI: An agent used DNS to reach an external chatbot
- 2026-09-21 TheRegister: Treasury chief says AI bosses, not their bots, will carry the can for criminal acts **
- 2026-09-25 SwarmTraces: Revealing the details of how OpenAI agents hacked Hugging Face
- 2026-09-28 TheRegister: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
- 2026-09-28 TheRegister: OpenAI agents went the long way round for UN data
- 2026-09-29 NYT: OpenAI Ignored Employees’ Warnings About Safely Testing A.I. Models **
- 2026-09-29 TheRegister: OpenAI benches GPT-6.1 Astra for overstepping the mark
- 2026-09-29 TheRegister: OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
** I submit for your consideration: These are not the result of Rogue AIs – but, in fact, their proximate root cause was simple criminal human negligence (at best).
